Bug 2541803 (CVE-2026-100656)

Summary: CVE-2026-100656 io.netty/netty-codec-http: Netty: Denial of Service via unbounded queue growth during HTTP request pipelining
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anthomas, ant, anujha, aschwart, asoldano, asyoung, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, boliveir, bstansbe, ccranfor, cescoffi, cmah, csuconic, dbruscin, dhanak, dlofthou, drichtar, drosa, dsimansk, ehelms, ehugonne, ewittman, fmariani, fmongiar, ggainey, gmalinko, gsmet, gtanzill, gtully, istudens, ivassile, iweiss, janstey, jbuscemi, jhollowa, jmartisk, jnethert, jpasqual, jpechane, jsherman, juwatts, jwon, kaycoth, kingland, kvanderr, manderse, mcarlett, mdellweg, mhulan, mnovotny, mosmerov, mposolda, msvehla, nipatil, nmoumoul, nwallace, olubyans, osousa, ozzy, pantinor, pberan, pcreech, pdelbell, pesilva, pjindal, pmackay, prichard, rchan, rgemmell, rgodfrey, rguimara, rkubis, rmartinc, rstancel, rstepani, sausingh, sbiarozk, sdawley, smallamp, ssilvert, sthirugn, sthorger, tbish, tcunning, thjenkin, tlavocat, tmalecek, varjain, vdosoudi, vmuzikar, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Netty. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending numerous pipelined HTTP/1.1 requests over a single connection while withholding reads. Netty's HTTP server codec stores unanswered requests in an internal queue without a size limit, leading to excessive memory consumption and an eventual application crash.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2542389    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-26 13:31:23 UTC
Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who pipelines HTTP/1.1 requests on a single connection while withholding reads on their own end (preventing responses from being flushed) can grow this queue without bound, causing unbounded heap growth and denial of service. Affected versions are 4.2.0.Final through 4.2.17.Final and all releases up to and including 4.1.137.Final; the issue is fixed in 4.2.18.Final and 4.1.138.Final.